Please enable JavaScript.
Coggle requires JavaScript to display documents.
INFORMATION SECURITY GOVERNANCE, Encourages organizations to integrate…
INFORMATION SECURITY GOVERNANCE
1.INFORMATION SECURITY GOVERNANCE
Definition & Key Concepts
Provides a framework to manage and protect important information assets.
Aligns information security with business objectives and risk management.
Governance → provides direction, manages risks and ensures responsible use of resources.
GRC → combines Governance + Risk Management + Compliance.
Importance
Information security is a strategic responsibility.
Must be addressed by top-level management.
Protects all information assets, not only IT assets.
Makes security part of the overall business strategy.
A purely technical IT approach is less effective.
ITGI Approach
Founded by ISACA in 1998.
Focuses on IT Governance and Information Security.
Provides knowledge and guidance for effective IT governance.
:ITGI Suggestions
Create a security-aware culture.
Align security investment with business strategy and risks.
Develop a comprehensive security program.
Require regular reports on security effectiveness.
5 Basic Outcomes
Strategic alignment
Risk management
Resource management
Performance measurement
Value delivery
Governance Frameworks
NCSP Industry Framework
Developed by Corporate Governance Task Force (CGTF) under NCSP.
Provides a framework for Information Security Governance.
Core Activities – NCSP
Conduct annual security evaluations.
Perform regular risk assessments.
Create policies based on risks.
Define clear roles and responsibilities.
Protect networks, systems and information.
Include security in the system life cycle.
Provide security awareness and training.
Test security policies regularly.
Create plans to fix security weaknesses.
Prepare incident response procedures.
Plan and test business continuity.
Use security best practices such as ISO 27000.
GES Program
Supports Enterprise Security Program (ESP)
BRC + management + stakeholders
Links security with risk management
Management vs Governance
Management
Implements controls
Manages risks
Daily operations
Recommends strategies
Governance
Sets direction
Provides oversight
Ensures accountability
Aligns security with business
Ensures compliance
Relationship
Governance
|
Sets direction
|
Management
|
Implements strategies
|
Security Goals Achieved
Roles & Responsibilities
Leadership
Set security direction
Build security culture
Support security teams
Ensure accountability
Leading by Example
Show commitment
Join risk assessments
Promote security awareness
Empowering Security Teams
Provide resources
Provide authority
Provide budget & support
Encourage teamwork
Driving Accountability
Clear roles
Clear responsibilities
Performance metrics
Shared responsibility
Encourages organizations to integrate security with corporate governance.